DSA-2026-368: Security Update for Dell PowerProtect Data Manager Multiple Vulnerabilities
Résumé: Dell PowerProtect Data Manager remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Détails
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-73600 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
|
CVE-2026-68860 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. |
6.8 |
|
|
CVE-2026-74769 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
6.5 |
|
|
CVE-2026-74768 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. |
4.1 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-73600 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
|
CVE-2026-68860 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. |
6.8 |
|
|
CVE-2026-74769 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
6.5 |
|
|
CVE-2026-74768 |
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. |
4.1 |
Produits concernés et mesure corrective
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-68860, CVE-2026-74769, CVE-2026-74768, CVE-2026-73600 |
Dell PowerProtect Data Manager |
Software |
Version 20.2.0.0 and prior |
20.3.0.0 |
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-68860, CVE-2026-74769, CVE-2026-74768, CVE-2026-73600 |
Dell PowerProtect Data Manager |
Software |
Version 20.2.0.0 and prior |
20.3.0.0 |
Historique des révisions
|
Revision |
Date |
Description |
|
1.0 |
2026-08-24 |
Initial Release |
|
2.0 |
2026-08-26 |
Updated Affected Versions in the Affected Product and Remediation table |
Remerciements
- Dell would like to thank Huynh Dinh Vu (WinD39) and Huynh Dinh Van for reporting this issue: CVE-2026-74769.
- Dell would like to thank saltedfish for reporting this issue: CVE-2026-74768.